What is a workplace safety and health audit?
Article 30.6 of Law 31/1995 establishes that employers who have not contracted their prevention services with a specialized entity must submit their prevention system to an external audit or evaluation. Royal Decree 39/1997 defines this as a management tool that aims to accurately reflect the prevention system, assessing its effectiveness and identifying deficiencies that could lead to non-compliance, in order to enable the adoption of decisions aimed at its improvement and enhancement.
The regulatory audit verifies how the risk assessment was carried out, whether the type and planning of preventive activities comply with regulations and the assessment, whether the company’s own or contracted resources are adequate and sufficient, and whether prevention is integrated into the company’s overall management system. It must be performed by a person or entity authorized by the labor authority, using the methodology, independence, and report content established by the Regulations.
Beyond legal requirements, many organizations conduct internal audits of their management systems and third-party audits to obtain or maintain certifications. These audits are voluntary, do not replace mandatory audits, and their results have no bearing on labor authorities, although they help keep the system active between mandatory audits.
Differences between regulatory audit, internal audit and certification
The term audit applies to three processes with different rules.
- Mandatory occupational health and safety audit. This audit is required in Spain for companies with their own occupational health and safety service or with designated workers who do not outsource all their activities. It is carried out by an authorized entity, follows the regulations, and its report must be kept available for the labor authority and workers’ representatives.
- Internal audit. A review that the organization itself conducts of its system using its own criteria or a reference standard. It is voluntary, serves for continuous improvement, and does not certify legal compliance.
- Certification audit. Evaluation by an accredited certification body against a standard such as ISO 45001. It is voluntary, verifies conformity with the standard, and does not exempt you from a mandatory regulatory audit.
Practical rule: If the company has its own preventative resources, it needs the mandatory audit even if it is certified; if it contracts all prevention services out to an external provider, it is not obligated to have one, but can voluntarily undergo an audit. An ISO 45001 certificate does not replace the mandatory audit report.
How is the regulatory audit performed?
The Prevention Services Regulations establish the scope, frequency, and content of the report. The first audit must be carried out within twelve months of the date on which the preventive activity plan is available, and repeated every four years, or every two years if the company carries out activities listed in Annex I; furthermore, it must be repeated when required by the labor authority in light of accident rates or other circumstances.
The usual process includes:
- Planning: definition of the scope (centers, activities, preventive modality), of the audit team and of the schedule, with consultation with the workers’ representatives.
- Document analysis: prevention plan, risk assessment, planning, concerts, prevention service report, training, health surveillance, coordination of activities and accident investigation.
- Verification at the center: interviews with management, supervisors, workers and their representatives, observation of positions and verification that the planned measures are implemented.
- Integration assessment: verifying that preventive functions are exercised at all levels and that company procedures incorporate prevention.
- Report: description of the system, methodology, results, deficiencies detected and conclusions on effectiveness, signed by the auditor and with the formalities of the Regulation.
- Follow-up: the company must incorporate the deficiencies into the planning, correct them and keep the report for the next audit and for the labor authority.
Companies with up to 50 employees without activities listed in Annex I may be exempt by notifying the labor authority as provided in Annex II of the Regulation, unless the authority decides otherwise due to the dangerousness of the activity or the accident rate.
Report content and elements to be audited
Article 31 of the Regulation sets out the minimum content of the audit report. In practice, the auditor examines:
- Integration of prevention. Prevention plan, roles and responsibilities, communication and participation channels.
- Risk assessment. Methodology, scope, updates, particularly vulnerable individuals, and review in the event of damage or changes.
- Planning and monitoring. Measures, deadlines, responsible parties, resources, and evidence of implementation and verification.
- Preventive organization. Adequacy and sufficiency of own resources and agreements, training of technicians and health activity.
- Cross-cutting activities. Information and training, emergencies, health surveillance, coordination of activities, control of equipment and PPE, accident investigation.
- Records and documentation. Mandatory documentation of article 23 of Law 31/1995 and traceability of actions.
The report must describe the system, methodology, results and conclusions, and identify the deficiencies detected and the recommendations for their correction, without the auditor being able to maintain commercial or other ties that compromise their independence.
Common errors and quality criteria
The most common shortcomings in regulatory auditing are:
- Failure to identify the obligation to be audited when establishing an in-house service or designating workers for part of the preventive activity.
- Exceeding the legal deadlines between audits or not carrying out the first one within twelve months of planning.
- Confusing ISO 45001 certification with the regulatory audit and disregarding the latter.
- Receive the report and do not transfer the deficiencies to the planning or correct them.
- Contracting audits with unauthorized entities or entities that are not independent from the external prevention service.
- Not informing or consulting the workers’ representatives, who should be aware of the report.
A useful audit is recognized because it produces a concrete report, with verifiable and prioritized deficiencies, which the company incorporates into its planning and closes before the next audit.
Practical example
Situation: a distribution company with 320 people, its own prevention service with two specialties and an external contract for the rest, faces its second regulatory audit.
- Scope. All centers and activities; verification of the preventive organization, the workplace risk assessment, the planning and the agreed health activity.
- Main findings. Preventive functions of warehouse managers not exercised in practice; planning with overdue measures without rescheduling; coordination of activities with carriers based on generic documentation.
- Resulting measures. Review of the prevention plan and specific training for managers; rescheduling of measures with those responsible and budget; new coordination procedure with written instructions for each center.
- Follow-up. Incorporation of deficiencies into planning with deadlines, internal verification at six months and retention of the report for the labor authority and for the next audit in four years.
Regulatory framework in Spain
- Law 31/1995, article 30.6 . It requires that the prevention system be subjected to an external audit or evaluation when the company does not contract the preventive activity with a specialized entity.
- Royal Decree 39/1997, Chapter V (Articles 29 to 33 bis) . It regulates the obligation to audit, the exemption by notification, the concept and objectives of the audit, the periodicity, the content of the report, the requirements of the auditors and voluntary audits.
- Order TIN/2504/2010 . Develops the authorization of persons and entities that can carry out the auditing activity of the prevention system of companies.
- Law 31/1995, articles 23 and 39. Documentation that must be available to the labor authority and competence of thehealth and safety committee to know the audit report.
OSH management system audits according to ISO 45001 are voluntary and international and are carried out by accredited certification bodies; in Latin America, some countries require periodic audits or self-assessments of the management system (for example, the minimum standards of the SG-SST in Colombia), with their own rules that do not coincide with the Spanish regulatory audit.
